Staying Ahead of the Ransomware Industry

Mark Lance, SVP of Digital Forensics and Incident Response (DFIR) and Threat Intelligence at GuidePoint Security, shares with Security magazine how ransomware is evolving — and how organizations can stay ahead.
Security magazine: Tell us about your background and experience in the security industry.
Lance: I’ve been in cybersecurity for nearly 27 years, with roughly the last 17 focused specifically on incident response. I first got into IT almost by accident, having built my first computer to play video games in college. While I was studying for my Microsoft certifications, a friend’s parent wanted to develop a security professional rather than hire one and gave me a shot at a managed security services startup. I came up through the analyst ranks, moving from analyst to senior, principal, and eventually to the first lead analyst the company ever had, because I’ve always had an inquisitive, puzzle-solving mindset that pulled me toward the investigative side of the work. From there I moved fully into incident response, eventually building out global IR functions at multiple companies, and over the years I’ve helped organizations respond to everything from business email compromise to ransomware to nation-state and APT activity. Today, as SVP of DFIR and Threat Intelligence at GuidePoint Security, that investigative instinct and technical background still drives how I approach the work.
Security: How have you seen ransomware evolve?
Lance: Ransomware started out very opportunistic, taking a shotgun approach aimed at individuals, locking their systems and demanding a ransom to get access back. Threat actors quickly realized organizations had deeper pockets and more to protect, so they shifted from individuals to companies, and then from broad targeting to deliberately going after specific organizations where operational impact would increase the odds of getting paid. As defenders matured and adopted backups, the actors adapted again by moving laterally, establishing persistence, and specifically targeting backups to take recovery off the table. When organizations responded with immutable and segmented backups, the actors pivoted to stealing data and threatening to publish it, which is how we arrived at the double-extortion model, and now even exfiltration-only extortion with no encryption at all. The through-line is that every time defenders raise the bar, the ransomware ecosystem evolves to protect its ability to monetize.
Security: What are the most effective entry points for malicious actors?
Lance: Despite all the new and novel techniques out there, the most effective initial entry points are still the old, foundational ones. We consistently see attackers get in through bad cyber hygiene, whether that’s unpatched systems, shadow IT, or exposed and vulnerable perimeter devices, along with successful phishing, lack of MFA, and more. The exploit or vulnerability may change, but the underlying methods to gain that first foothold have stayed remarkably consistent. Where we actually see the new and novel tradecraft is after they’re already inside, when they leverage that access to move laterally, tunnel, and exfiltrate data. In other words, they don’t need to reinvent how they get in when the basics keep working.
Security: How can organizations stay ahead of the ransomware industry?
Lance: It really comes down to awareness and education, and turning that into enablement. Every organization should have an incident response plan, and while it doesn’t need to be an exhaustive, task-by-task document, it should answer the key questions before an incident hits, such as who our third parties are, whether we have external counsel and cyber insurance, whether we have an IR service provider on call, how we determine severity, and who makes the critical decisions. That plan should be paired with playbooks tailored to the threats most relevant to your environment, because ransomware can impact any organization of any size across any vertical, from small businesses to the Fortune 100s. On top of that, the foundational controls still matter enormously, including MFA, EDR and appropriate visibility, network segmentation, and privileged access management. Staying ahead is really about combining those fundamentals with realistic threat modeling for what’s actually most likely to impact your organization.
Security: Anything else you would like to add?
Lance: The one thing I’d emphasize is enablement, awareness and information sharing. One of the biggest shifts I’ve seen over 27 years is the stigma around having an incident, because historically there was this idea that you didn’t talk about a breach since you should be ashamed of it. But in today’s threat landscape, where attacks are inevitable, this is something everyone is dealing with and there’s real value in sharing our experiences so others can learn from them and avoid the same fate. Even among competitors, I’m a strong proponent of getting together and sharing, not trade secrets or intellectual property, but the tactics and lessons learned, because we’re all facing the same adversaries. We’re far more effective against them when we work as a community than when we go it alone.
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!





